?
Solved

TLS 1.1  Should I use QWORD or DWORD and what ciphers should be added ?

Posted on 2014-11-10
5
Medium Priority
?
349 Views
Last Modified: 2014-11-11
Windows 2008 R2 server, IIS 7.0.  I turned off the SSL 3.0 and turned on the TLS 1.1 in the registiry using the Microsoft instructions.  They scanned the server again and they are saying it's still  vunerable.

I used QWORD in the registry settings instead of DWORD since it's a 64 bit operating system.  Is QWORD Correct?

I was not sure if there were specific ciphers I needed to turn off also that may still be causing the problem?
0
Comment
Question by:kdschool
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 82

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 400 total points
ID: 40434259
they should be DWORD not QWORD
set-perfectFSecutity.ps1.txt
0
 
LVL 64

Accepted Solution

by:
btan earned 1600 total points
ID: 40434303
indeed it is DWORD (32-bit) Value for client and server. And collectively do reference to Microsoft security advisory for the mitigation of the recent SSLv3 Poodle vulnerability. Note there are previous vulnerability such as BEAST which is along the line for disabling SSL v3 too. check out the browser setting and it will be good to push down as GPO to all managed machines and manually configure it for the standalone machine

https://technet.microsoft.com/en-us/library/security/3009008.aspx

You can also catch the screenshot steps below.

https://www.digicert.com/ssl-support/iis-disabling-ssl-v3.htm
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40434472
I gave up using manual registry entries.
Try this free tool instead:

https://www.nartac.com/Products/IISCrypto/

Simon.
0
 
LVL 64

Expert Comment

by:btan
ID: 40434508
there is also some sharing of key note running reg, pls see in SAN posting (esp the feedbacks)
https://isc.sans.edu/forums/diary/POODLE+Turning+off+SSLv3+for+various+servers+and+client/18837
0
 

Author Closing Comment

by:kdschool
ID: 40435786
Can't use a tool through the firewall.  Thank you so much for the images.  That was spot on.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Today I came across an interesting issue that had me pulling my hair out.  I was troubleshooting a new internal web site which uses integrated security instead of anonymous.  When browsing the site from my laptop, I was able to access it with no iss…
#SSL #TLS #Citrix #HTTPS #PKI #Compliance #Certificate #Encryption #StoreFront #Web Interface #Citrix XenApp
Michael from AdRem Software outlines event notifications and Automatic Corrective Actions in network monitoring. Automatic Corrective Actions are scripts, which can automatically run upon discovery of a certain undesirable condition in your network.…
In this brief tutorial Pawel from AdRem Software explains how you can quickly find out which services are running on your network, or what are the IP addresses of servers responsible for each service. Software used is freeware NetCrunch Tools (https…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question